Chaos Engineering Platform  ·  View 08 of 21  ·  Structure

Integration Surface

Five read-only inputs, five things it tells or acts on, and nothing it writes back.

Editable source SVG draw.io All views
Read-only inputs Service catalogue Dependency graph SLO store Cloud Monitoring Incident feed Chaos Engineering Platform Platform API definitions, runs Guardrail engine Lease issuer Run event topic Pub/Sub Outputs and acted-on systems Injection agents Incident platform Deployment pipeline Target dashboards Chat and on-call ownership graph edges SLI defs signals open incidents leases findings verdict annotation pre-run notice Integration Surface — What It Reads, What It Tells External / third party Application we own Security / platform Queue / topic synchronous event / async Nothing on the left is written by this platform. A stale read blocks a run rather than degrading it silently. Identity is on view 21. v 1.0 · owner Reliability Architecture · date 2026-09

Decisions

  • Every left-hand system is read-only. The platform consumes the inventory it does not own, and a stale read blocks a run rather than degrading it silently.
  • The incident feed is an input with veto power, not an advisory: an open incident of configured severity suspends injection without a human deciding.
  • Run state transitions go out on a durable topic, so the incident platform, the catalogue and reporting all read the same events rather than polling the API.

Assumptions

  • Service inventory and dependency graph no older than 24 hours, enforced as a hard block rather than a warning.
  • Pre-run notification 10 minutes ahead for scheduled runs, immediate for ad-hoc.

Accepted clutter

  • Four route-check warnings remain on this page: with five satellites a side, adjacent edge labels sit close. Shortening them further would cost meaning.